Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

aa.com

aa.com

Discovered 2024-04-19 12:07 UTC
Est. attack date 2021-11-20
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

aa.com

Infostealer activity detected by HudsonRock

Compromised Employees: 313

Compromised Users: 23065

Third Party Employee Credentials: 710


External Attack Surface: 142


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • aa-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • lucidlink-verification=HETATCH0P2YF31VDDHX9EYHNFC
  • echomark-domain-verification=019cc446-264b-7102-80a6-de28dea063d9
  • google-site-verification=TqCzk3YeRjQC3aV8ZnhzLZ_4PG3v2eLN7TCrZEoIRas
  • cisco-ci-domain-verification=4b9e6838d89e76ea60df2660c3ba899fcb8963003c0245109ba6bf614c480d25
  • v=spf1 include:spf.protection.outlook.com include:onprem.aa.com include:_spf-dc4.sapsf.com include:spf.aa.com" " ip4:169.55.103.7 ip4:169.55.103.8 ip4:169.44.200.37" " ip4:169.44.200.38 ip4:136.147.176.0/20 ip4:13.111.0.0/18 ip4:70.42.227.151 ip4:70.42.227.152 ip4:146.20.91.152" " ip4:146.20.91.153 ip4:66.48.80.132 ip4:204.232.172.40 ip4:161.47.34.7 ip4:108.166.43.0/24 ip4:173.203.2.22" " ip4:12.104.201.5 ip4:91.198.224.29/32 ip4:194.37.255.29/32 ~all
  • google-site-verification=dZIYXDh-hXpVIxwE5adItfWo3XPuENVm6D_zV_8Ffqo
  • neat-pulse-domain-verification-6X5jwmM=62378b21-1f50-4147-914d-c8b5c33a101a
  • uber-domain-verification=17cf8bf3-d883-40f8-b478-95fc8d6f6ccb
  • _yy4ib5weq0yj733yz1i54zjbl3t45wm
  • r9416799dt2rlt0o47f0hja26a
  • Dynatrace-site-verification=928cac27-db8d-419b-8167-42fe8a72b013__78n145kc0rt4782o06drskla20
  • successfactors-site-verification=ODk2NmM5NzI1MTQyNWFkMGM5NmY5YWYxNmZkZGM2NWJhOGE4OWQ1ODYwNmQyOGYyOGU4MjcyMjk2MmZjMzE4Ng==
  • mongodb-site-verification=rE3HOnngegvIjlv04r8bF57HhGEkKRP9
  • google-site-verification=IWp1_J5EtXQ3m0h3FHU8iin0y8KB5NrAUmIRWVZUEgM
  • webexdomainverification.4e7d270283bce33ee053ad06fc0a283e=17f431d2-cc96-4a41-91f5-53b3fb8ec59e
  • amazonses:WWgi/cimZNBMUTaL6vENIdRE+olrkfUVqq0nKtFUU3s=
  • smartsheet-site-validation=o5w--wmz-ypDcMIaYltIoc8rl9GVtLOz
  • google-site-verification=A34USNZ3lUylO3bw2hecHnCdud_Ibf5QQGp8cyUPItI
  • ms-domain-verification=f6d48ff7-7f5d-497d-a030-60de7d6cc16d
  • apple-domain-verification=VSG92QlVEH8qFrSK
  • mongodb-site-verification=FEXmQB6dWXMrdS1bmQEsBMRXfglMmuNr
  • atlassian-domain-verification=w7x4okezn3mefO16AO/CimT5Om4IJ0N6v09XH/wm8dj3vnt/x9CL5WZKT1BFmpuk
  • jamf-site-verification=jPwbspOvavSmZtgfszxLAg
  • edb-biganimal-verification=UgPBZw7tazPQEGN4NZu7kcHqBkKAotEx
  • ms-domain-verification=7882b656-bb77-46a7-ace1-5e98991a8f60
  • asv=c3b52355d8e462ae1e38b8f28ee8b818
  • amazonses:HO/GT9BMm+jjDYSXpPnCsDJG/Apme4R8qI2Pd/rwpek=
  • webexdomainverification.4C675B8BBCC3B136E053AB06FC0A3F65=f583bef7-8cf0-486c-8da5-964d3ebc02b6
  • ms-domain-verification=66cc83f8-4dcf-4e56-93ef-db981612bcef
  • google-site-verification=MlCd58DTNUAKwFUH4uo5bi6oF5672n4YR0pfSr8DfQo
  • infoblox-domain-mastery=dc6fb6dbf66824ac06bb988f8283d469d2e0f69b271ea676a41d7f0a23f406abed
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail LucidLink JamF Cisco Cisco Webex

Leak Screenshot:

Leak Screenshot